Vulnerability Description
An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to escalate privileges to the user that wpa_supplicant runs as (usually root). Membership in the netdev group or access to the dbus interface of wpa_supplicant allow an unprivileged user to specify an arbitrary path to a module to be loaded by the wpa_supplicant process; other escalation paths might exist.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| W1.Fi | Wpa Supplicant | - |
| Canonical | Ubuntu Linux | - |
Related Weaknesses (CWE)
References
- https://bugs.launchpad.net/ubuntu/+source/wpa/+bug/2067613ExploitIssue Tracking
- https://snyk.io/blog/abusing-ubuntu-root-privilege-escalation/ExploitThird Party Advisory
- https://ubuntu.com/security/notices/USN-6945-1Vendor Advisory
FAQ
What is CVE-2024-5290?
CVE-2024-5290 is a vulnerability with a CVSS score of 8.8 (HIGH). An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to escalate privileges to the user that wpa_supplicant...
How severe is CVE-2024-5290?
CVE-2024-5290 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-5290?
Check the references section above for vendor advisories and patch information. Affected products include: W1.Fi Wpa Supplicant, Canonical Ubuntu Linux.